CVE-2026-94285: Out-of-bounds read in libX11's byte-oriented codeset parser
Published Sep 28, 2026
·Updated
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Affected Software
1 affected component
X.Org libX11<1.8.14
Event History
Sep 28, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
X clients using libX11 before 1.8.14 are exposed when they attach to a malicious X server. The issue affects the byte-oriented codeset parser.
2
What must an attacker be able to do to trigger the flaw?
An attacker must operate or control an X server that a vulnerable X client connects to. Exploitation can crash the attached client; the provided information does not describe further impact.
3
How can I determine whether remediation is needed?
Check the libX11 version used by affected X clients. Versions before 1.8.14 need to be updated to 1.8.14 or later.